Description
WordPress Plugin Wrapper Link Elementor contains malicous code. Exploiting this issue may allow an attacker to create a new administrative user account, thus compromising the affected application, and possibly the webserver or computer. WordPress Plugin Wrapper Link Elementor versions 1.0.2 - 1.0.3 are affected.
Remediation
Update to plugin version 1.0.5 or latest
References
Related Vulnerabilities
Telerik Web UI Deserialization of Untrusted Data Vulnerability (CVE-2019-18935)
WordPress Plugin AppPresser-Mobile App Framework Security Bypass (4.3.0)
Jboss EAP Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2019-9511)
phpMyAdmin Permissions, Privileges, and Access Controls Vulnerability (CVE-2016-9849)